Skip to main content

Vendor archive

ninjateam CVEs

Beta · best-effort

36 CVEs tagged to vendor ninjateam4 Critical, 6 High, 25 Medium, 1 Low, 0 Unrated.

CVE-2023-6592

Published Jan 16, 2024

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51406

Published Jan 8, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest Word…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5740

Published Oct 25, 2023

The Live Chat with Facebook Messenger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'messenger' shortcode in all versions up to, and including…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-4862

Published Oct 16, 2023

The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4861

Published Oct 16, 2023

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4827

Published Oct 16, 2023

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users pe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36718

Published Jun 7, 2023

The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2093

Published Jul 11, 2022

The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24385

Published Jul 12, 2021

The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerabi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24143

Published Jul 7, 2021

Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24142

Published Jul 7, 2021

Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-36 of 36 CVEsPage 2 of 2